AWS Certified SysOps Administrator – AssociateSecurity and ComplianceEasy

A company is developing a new application that processes sensitive customer data. The application will store session tokens, API keys, and database credentials. The security team requires these secrets to be automatically rotated every 90 days and encrypted at rest and in transit. Which AWS service is BEST suited for managing these requirements?

  1. AAmazon S3
  2. BAWS Secrets Manager
  3. CAWS Systems Manager Parameter Store
  4. DAWS Key Management Service (KMS)
Show answer & explanation

Correct answer: B. AWS Secrets Manager

AWS Secrets Manager is specifically designed for securely storing and managing application secrets. It offers built-in features for automatic rotation, encryption at rest and in transit, and fine-grained access control, directly addressing all the stated requirements.

Why the other options are wrong

  • A. Amazon S3 is an object storage service and is not designed for managing application secrets with automatic rotation capabilities.
  • C. Parameter Store can store sensitive data, but its automatic rotation capabilities are limited and typically require custom automation, unlike Secrets Manager.
  • D. KMS is used for managing encryption keys, not application secrets directly, though Secrets Manager uses KMS for encryption.

AWS Secrets Manager

AWS Secrets Manager helps you protect access to your applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

  • Automatic secret rotation.
  • Encrypts secrets at rest and in transit.
  • Integrates with other AWS services.
  • Fine-grained access control.

Memory trick: Secrets Manager: Rotate, Encrypt, Control.

More Security and Compliance questions